Integrity and Confidentiality Principle
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.
Overview
27 sources · Aug 27, 2026Legal Framework
The integrity and confidentiality principle is codified in Article 5(1)(f) GDPR, one of the six foundational principles governing all personal data processing. It requires controllers to ensure appropriate security of personal data throughout the processing lifecycle. The provision is deliberately broad, encompassing both technical measures (encryption, access controls, pseudonymisation) and organisational measures (staff training, policies, processor oversight).
"processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures"
— GDPR Art. 5(1)(f)
Recital 75 elaborates the risk landscape that the principle addresses, enumerating physical, material, and non-material damage scenarios — from identity theft and financial loss to discrimination and loss of confidentiality of professionally protected data. Recital 85 connects the principle to breach notification obligations, establishing that failure to maintain appropriate security triggers both the Article 5(1)(f) violation and the Article 33/34 notification duties.
The principle operates alongside, but is distinct from, Article 32 GDPR (security of processing), which provides the operational implementation framework. Article 5(1)(f) sets the principle; Article 32 sets the specific requirements for risk assessment, pseudonymisation, and encryption.
Key Developments
Enforcement authorities across the EU have applied Article 5(1)(f) to both controllers and processors, with particular focus on inadequate technical safeguards. The Croatian DPA sanctioned an IT services provider after a security breach exposed personal data of over 28,000 individuals, finding the processor failed to implement measures proportionate to foreseeable risks:
"The incident occurred because the IT provider had not taken the necessary measures to achieve an adequate level of security in accordance with existing and foreseeable risks."
— Croatian DPA — IT services company
The Italian Garante similarly found against Roma Capitale, where data flows were transmitted through insecure channels and officials could query license plate data en masse without controls. The Garante treated the absence of access restrictions as a direct Article 5(1)(f) failure, not merely an Article 32 deficiency.
Dutch courts have addressed the principle in the context of unauthorised access by employees. In a case against a municipality, the court held that where a controller cannot identify who accessed personal data or for what purpose, the burden falls entirely on the controller:
"Dat het college geen informatie heeft over wie (binnen de gemeente) de persoonsgegevens heeft geraadpleegd en met welk doel is een omstandigheid die volledig voor rekening en risico van het college komt."
— Rechtbank — AVG en verzoek om schadevergoeding
The EDPB's Guidelines 9/2022 clarify that the principle's protective scope extends beyond traditional confidentiality breaches:
"unauthorised or unlawful processing may include disclosure of personal data to (or access by) recipients who are not authorised to receive (or access) the data, or any other form of process"
— EDPB Guidelines 9/2022 §14
Status of the Debate
The integrity and confidentiality principle is actively contested in court. While the textual standard — "appropriate" security — appears settled, its application to specific factual contexts remains in flux. Courts have diverged on the threshold for what constitutes "appropriate" measures, particularly where controllers face resource constraints or where processors rather than controllers are held primarily responsible. The open question is whether courts will adopt a strict risk-proportionality test (where any foreseeable breach demonstrates inadequacy) or a reasonableness standard (where documented risk assessments and layered controls may suffice even when breached). Resolution will likely come from CJEU preliminary references on the interplay between Article 5(1)(f) and Article 32, particularly regarding whether processor failures can constitute controller violations of the principle itself.
Practical Guidance
Conduct and document risk assessments mapping to Recital 75 risk categories — discrimination, identity theft, financial loss, reputational damage — to demonstrate that security measures are proportionate to identified risks.
Implement layered access controls that log and attribute every instance of personal data access. The Dutch municipality case demonstrates that inability to identify who accessed data constitutes an independent violation.
Vet processors against expertise, reliability, and resource criteria before engagement, and contractually mandate security standards. The Croatian enforcement action shows that processor failures expose both the processor and the controller to liability.
Secure all data transmission channels — the Roma Capitale decision confirms that transmitting personal data through unencrypted or insecure channels violates Article 5(1)(f) directly, not just Article 32.
Integrate breach response with the security principle: maintain incident detection and notification procedures aligned with Recital 85, ensuring that any security failure is assessed for both notification obligations and systemic remediation under the accountability principle.
why this is here
unauthorised disclosure of, or access to, personal data
The definition of breach directly relates to unauthorised access or disclosure, which is a violation of integrity and confidentiality principles.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
each of the aforementioned principles and the ensuing protection of rights
Integrity and confidentiality are among Article 5 principles, but the document does not specifically single them out.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the ePD protects users’ privacy not only in relation to the confidentiality of their information but also by safeguarding the integrity of the user’s terminal equipment
Mentions integrity but not as a GDPR principle.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
security and privacy of connected vehicles
The document mentions security in the context of related works, but does not specifically address integrity and confidentiality as a principle.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 83 Case Law · all 41 Guidance · all 198 Enforcement · all 28 Literature · all 31 News